Trust Center

Security and privacy documented, not asserted

Insight about people demands strict safeguards. This page describes how QuestPulse is built, operated and governed, and where responsibility sits.

Documentation

Security and privacy in QuestPulse

01
Security architecture
Separated environments, least privilege between components, encryption in transit and at rest, and logging of administrative operations.
02
Data flow and data location
Data is stored and processed within the EEA, on Azure Norway East. Data flow from collection to aggregated insight is documented per environment.
03
Access control
Login through your own identity provider using SSO. Access is role based, granted per organisational area and logged.
04
Aggregation and protection of the individual
Individual answers are never shared with the employer. Insight appears only when the group is large enough to prevent identification.
05
Retention and deletion
Retention is set per data category and agreed in the data processing agreement. Data is deleted or returned on termination.
06
Sub-processors
A current list of sub-processors, their purpose and location is provided as an annex to the data processing agreement.
07
Incident handling
Defined routines for detection, classification, notification and follow-up, with agreed notification deadlines towards the controller.
08
Continuity and recovery
Backup, recovery routines and defined recovery objectives, described in the operational documentation.
09
Privacy
Built to GDPR article 25 with data minimisation. You are the controller, QuestPulse is the processor under an article 28 agreement.
10
Model governance and human control
Automated analysis is used to prioritise and summarise, never to make decisions about individuals. Output is explainable and can be overridden by a person.
11
Agreements and documentation
Data processing agreement, sub-processor annex and security documentation are shared on request as part of a procurement or evaluation process.
12
Security contact point
Security enquiries, vulnerability reports and documentation requests go to support@questpulse.no.

Documentation

Request the DPA and security documentation

Note in the message field which documentation you need, and we will send it over.

hei@questpulse.no
support@questpulse.no
Digital Coach Hub AS